H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
BID:6537
Info
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
| Bugtraq ID: | 6537 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
Positive Software Corporation H-Sphere 2.3 RC3 |
| Not Vulnerable: |
Positive Software Corporation H-Sphere 2.4 |
Discussion
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
The H-Sphere Webshell component is prone to a remote command execution vulnerability.
This issue exists in the 'command.C' source file and is due to insufficient validation of input supplied via the 'mode' URI parameter. It is possible for a remote attacker to supply shell commands via this URI parameter, which will be executed with the privileges of Webshell.
It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.
The H-Sphere Webshell component is prone to a remote command execution vulnerability.
This issue exists in the 'command.C' source file and is due to insufficient validation of input supplied via the 'mode' URI parameter. It is possible for a remote attacker to supply shell commands via this URI parameter, which will be executed with the privileges of Webshell.
It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.
Exploit / POC
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
Solution:
The vendor has confirmed this issue and has released fixes. Users are advised to upgrade as soon as possible.
Fixes:
Positive Software Corporation H-Sphere 2.3 RC3
-
Positive Software H-Sphere 2.4 Patch
http://www.psoft.net/shiv/U23/u-webshell.tgz
References
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
References:
References:
- Positive Software Homepage (Positive Software)
- Remote root vuln in HSphere WebShell (Carl Livitt
)